The documentation, changelog, repository tests, and Apache-2.0 licensing provide useful adoption and maintenance context. The nontrivial dependency surface and absent security policy add modest uncertainty for long-term support.
43%
Total Score
0
75
50
The package has 70 releases over more than 10 years, but its latest release was in November 2020 and it had no releases in the following five years and ten months. The long historical cadence is outweighed by the prolonged release gap.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push being in December 2020. This is strong evidence of abandonment risk for a framework integration package.
The repository has zero stars, zero watchers, and one fork, offering little evidence of an active user or contributor community. Popularity is supporting evidence only, so this modestly reinforces the maintenance concern.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning automation is a hygiene limitation rather than a standalone adoption blocker.
No security policy was found in the repository. That is a transparency and vulnerability-reporting gap, although it is less significant than the prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.2 | — | — |
ramsey/uuid Version ^3.0|^4.0 | — | — |
illuminate/http Version ^8.0 | — | — |
neomerx/json-api Version ^1.0.3 | — | — |
illuminate/console Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.